The Architecture Brief Your OT Review Has Been Waiting For.
TSA SD 1580/82-2022-01C extends cybersecurity expectations to OT and now classifies Positive Train Control as a Critical Cyber System. RTIS/RVIS sensors are one-way outbound transmitters — one ~30KB cropped JPEG per entry event, no return channel, no X-LST or UMbRA data on the device. A compromised sensor cannot expose what it does not hold.
No return channel. No commands. No watchlist or identity data flowing back to the device.
No X-LST entries. No UMbRA records. No biometric templates. Sensor compromise cannot expose what is not there.
One cropped JPEG, outbound. The lowest possible OT risk classification — non-sensitive, low-bandwidth, outbound-only.
Type II SOC 2 with documented data-flow, penetration test summary, and DPA available on request.
Most Biometric Sensors Fail OT Security Review. RTIS/RVIS Is Designed to Pass.
You are the most common blocker in the freight rail security sale — and that is the right thing for you to be. Your job is to keep the OT network defensible under TSA SD 1580/82-2022-01C and the broader Surface Transportation directive series. Most biometric sensors fail OT review at first contact: they hold watchlist entries on the device, they hold biometric templates on the device, they require a two-way API connection to a vendor cloud, and the vendor classification at OT review is *sensitive data endpoint on the operational network* — which is exactly the classification the directive was written to constrain. The Safience sensor architecture is built to fail none of those tests. It is one-way outbound. It holds no sensitive data. It transmits one ~30KB cropped JPEG per entry event. It does not receive watchlist data, identity records, or any return channel. Every match happens at the Safience platform tier, not on the device. A compromised sensor cannot expose your X-LST. The OT risk classification falls into the lowest category your framework allows. We provide a two-page data-flow diagram, a SOC 2 Type II report, a penetration-test summary, and a DPA before your security architecture review begins.
-
The On-Device Sensitive Data Gap
Most biometric sensors hold the watchlist on the device for "edge matching." That design makes the device a sensitive data endpoint by definition. Under TSA SD 1580/82, that classification triggers an extended OT review and typically fails it. RTIS/RVIS sensors hold no watchlist, no biometric templates, and no identity data — matching is platform-level.
-
The Two-Way API Gap
Most biometric vendors require a two-way API connection — sensor to vendor cloud and back — for enrollment, list updates, and synchronization. That API surface is the highest-consequence breach scenario. RTIS/RVIS has no return channel. The sensor is a one-way outbound transmitter. There is no command path from the platform to the device.
-
The Vendor Documentation Gap
Most vendors hand your team marketing material and ask for an OT review to clear it. Safience hands your team a two-page data-flow diagram, a SOC 2 Type II report, a penetration-test summary, and a DPA — before the review begins.
-
The Encrypted Identity Data on OT Gap
Most "edge biometric" vendors point to encryption on the device as defense in depth. Encrypted sensitive data on an OT network is still sensitive data on an OT network — the directive does not exempt encrypted data. RTIS/RVIS removes the data entirely, not just the readable form of it.
Your OT Architecture Review of RTIS/RVIS: Step by Step
Most CISOs need three documents and one architecture call to clear RTIS/RVIS. Here is the path.
-
Read the data-flow brief
We send a two-page architecture diagram showing: sensor capture → one-way outbound transmission (~30KB JPEG per event) → platform matching → RAC adjudication → carrier notification. No return channel. No on-device sensitive data.
-
Review SOC 2 and pentest evidence
We send the current SOC 2 Type II report and the most recent penetration-test summary. Your team confirms the control environment meets your vendor security threshold.
-
Sign the DPA
We send a DPA template that establishes the carrier as data controller for X-LST and Safience as the platform-tier processor. No new data controller relationship is created on the carrier side.
-
Classify the sensor under SD 1580/82
Your OT team classifies the sensor in your existing framework. The expected classification under the directive’s risk framework: outbound-only, non-sensitive, low-bandwidth — the lowest available tier.
-
Approve the deployment
With the architecture brief, SOC 2, pentest summary, and DPA on file, the sensor clears review on a single pass. Pilot deployment goes live in days; OT cutover is not required.
Typical Biometric Sensor vs. Safience Sensor Architecture
| Capability | Typical Biometric Sensor | Safience RTIS/RVIS Sensor |
|---|---|---|
| Direction of traffic | Two-way API | One-way outbound only |
| Watchlist on device | Yes (for "edge matching") | No — platform-level only |
| Biometric template on device | Stored | Not stored; instant non-match deletion |
| Return channel from vendor | Required for enrollment/sync | None |
| Per-event payload | Continuous video stream or large image | One ~30KB cropped JPEG |
| OT classification under SD 1580/82 | Sensitive data endpoint | Outbound-only, non-sensitive, low-bandwidth |
| Vendor documentation provided up front | Marketing material | Data-flow brief, SOC 2 Type II, pentest summary, DPA |
| Encrypted on-device data | "Defense in depth" | No on-device sensitive data to encrypt |
| Sensor compromise consequence | X-LST and identity data exposure | Cannot expose what is not on the device |
Products for the CISO
The CISO sale is the architecture sale. RTIS/RVIS sensor design is the whole product story; X-LST, UMbRA, eMotive, RAC, and QAPLA all live above the OT boundary.
RTIS / RVIS Sensor Architecture
One-way outbound. ~30KB per event. No on-device sensitive data. No two-way API surface. No edge watchlist.
Platform-Level Matching
All X-LST adjudication and UMbRA comparison happens in the Safience platform tier, not on the carrier's OT network.
RAC Adjudication
Human verification at aankh.biometrica.com before any carrier notification. Architecturally required, not procedural.
Documentation Pack
Data-flow brief, SOC 2 Type II report, penetration-test summary, DPA. Ready before review begins.
Where Next
The CISO clearance unlocks the rest of the buyer's group.
Get the Architecture Brief Before Procurement Reaches You.
Schedule a 30-minute architecture call with our security engineering team. You will leave with the two-page data-flow diagram, the SOC 2 Type II report, the penetration-test summary, and the DPA — everything you need to clear the OT security review on the first pass.